Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
ID: d1860435-7b8a-5053-bd31-e274bf859967
STIX ID: report--d1860435-7b8a-5053-bd31-e274bf859967
Feed Name: The Hacker News
Researchers disclosed an active supply-chain worm campaign called SANDWORM_MODE that uses at least 19 malicious npm packages, a weaponized GitHub Action, and an MCP injection module to harvest developer credentials, SSH keys, cloud/LLM API keys, and cryptocurrency keys while self-propagating via stolen npm and GitHub identities; the malware includes a delayed second stage, polymorphic evasion capabilities, and an optional destructive wiper. Immediate remediation recommended: remove affected packages, rotate tokens and CI secrets, and audit package.json, lockfiles, and .github/workflows for unauthorized changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
